@slidev/cli
Presentation slides for developers
34
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
antfu_kerman
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@shikijs/vitepress-twoslash | AI (dependencies): Shiki twoslash integration; expected for slidev's code highlighting. | ai | |
| dependencies | unvetted-dep:markdown-it-mdc | AI (dependencies): Markdown extension for MDC syntax; expected dependency for slidev's markdown pipeline. | ai | |
| dependencies | unvetted-dep:shiki-magic-move | AI (dependencies): Shiki-based animation library by same author (antfu); expected for slidev. | ai | |
| dependencies | unvetted-dep:magic-string-stack | AI (dependencies): Source-map utility; expected for slidev's build pipeline. | ai | |
| dependencies | unvetted-dep:@iconify-json/carbon | AI (dependencies): Icon set; expected bundled asset for slidev UI. | ai | |
| dependencies | unvetted-dep:@unocss/extractor-mdc | AI (dependencies): UnoCSS extractor; expected for slidev's CSS pipeline. | ai | |
| dependencies | unvetted-dep:@lillallol/outline-pdf | AI (dependencies): PDF outline utility; expected for slidev's PDF export feature. | ai | |
| dependencies | unvetted-dep:@iconify-json/svg-spinners | AI (dependencies): Icon set; expected bundled asset for slidev UI. | ai | |
| dependencies | unvetted-dep:obug | AI (dependencies): obug is a legitimate debug-replacement package; replaces debug in this version, consistent with ecosystem author's tooling. | ai | |
| phantom-deps | phantom-dep:@shikijs/twoslash | AI (phantom-deps): Used via @shikijs/vitepress-twoslash integration; stable false positive. | ai | |
| phantom-deps | phantom-dep:@iconify-json/carbon | AI (phantom-deps): Icon data loaded at runtime; stable false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @slidev/cli is the official Slidev CLI; no relation to joi. | ai | |
| phantom-deps | phantom-dep:@iconify-json/svg-spinners | AI (phantom-deps): Icon data loaded at runtime; stable false positive. | ai | |
| phantom-deps | phantom-dep:@unocss/extractor-mdc | AI (phantom-deps): UnoCSS extractor loaded via config; stable false positive. | ai | |
| phantom-deps | phantom-dep:local-pkg | AI (phantom-deps): Used indirectly via plugin/config resolution in this monorepo CLI; stable false positive. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): TypeScript is a peer/tooling dep used by jiti/tsdown at runtime; stable false positive. | ai | |
| phantom-deps | phantom-dep:htmlparser2 | AI (phantom-deps): Used indirectly in markdown processing pipeline; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:magic-string | AI (phantom-deps): Used via magic-string-stack and other plugins; stable false positive. | ai | |
| phantom-deps | phantom-dep:resolve-from | AI (phantom-deps): Used in module resolution helpers; stable false positive. | ai | |
| phantom-deps | phantom-dep:@unocss/reset | AI (phantom-deps): Bundled asset dep for UnoCSS; stable false positive. | ai | |
| phantom-deps | phantom-dep:monaco-editor | AI (phantom-deps): Loaded dynamically for editor feature; stable false positive. | ai | |
| phantom-deps | phantom-dep:@iconify-json/ph | AI (phantom-deps): Icon data loaded at runtime by unplugin-icons; stable false positive. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 52.18.0 | 74 / 3 | |
| 52.17.2 | 75 / 3 | |
| 52.17.1 | 74 / 3 | |
| 52.17.0 | 74 / 3 | |
| 52.16.0 | 71 / 3 | |
| 52.15.2 | 71 / 3 | |
| 52.15.1 | 71 / 3 | |
| 52.15.0 | 71 / 3 | |
| 52.14.1 | 70 / 3 | |
| 52.14.0 | 70 / 3 | |
| 52.13.0 | 70 / 3 | |
| 52.12.0 | 70 / 3 | |
| 52.11.5 | 70 / 3 | |
| 52.11.4 | 70 / 3 | |
| 52.11.3 | 70 / 3 | |
| 52.11.2 | 70 / 3 | |
| 52.11.1 | 70 / 3 | |
| 52.11.0 | 70 / 3 | |
| 52.10.1 | 70 / 3 | |
| 52.10.0 | 70 / 3 | |
| 52.9.1 | 70 / 3 | |
| 52.9.0 | 70 / 3 | |
| 52.8.0 | 70 / 3 | |
| 52.7.0 | 70 / 3 | |
| 52.6.0 | 70 / 3 | |
| 52.5.0 | 70 / 3 | |
| 52.4.0 | 70 / 3 | |
| 52.3.0 | 70 / 3 | |
| 52.2.5 | 70 / 3 | |
| 52.2.4 | 70 / 3 | |
| 52.2.3 | 70 / 3 | |
| 52.1.0 | 70 / 3 | |
| 52.0.1 | 70 / 3 | |
| 52.0.0 | 70 / 3 |
v52.18.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v52.17.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v52.17.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v52.17.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.